I suspect the people who frequent this forum have some appreciation for how much power you give someone when you hand them (or their service) your API key. They instantly have access to your inventory, your battle stats, who you're sending messages with, when you're on/off drug cooldown, etc. This is a silly amount of personal information to give out to a script/service that may have limited functionality, like notifying you when you receive a new message.
I would love to see a system where players can have multiple API keys (a max of 10, perhaps?) and control which endpoints each key has access to. I would be much more likely to sign up for services if I could restrict their access to just the information they need. Maybe this control could be toggled as "advanced controls" so as not to confuse players that do not care.
I'm posting this in the API forums to solicit feedback. Do you think this would be a worthwhile investment of developer time? Do you have suggestions for how it could be best implemented?
+1
basically exactly as you said, or maybe have "app-registry" where you have to authorize access from an app and set per-app perms?
kinda like discord, you register your app in one place and then per-server can change perms.
not sure how to implement an authorization system though.
I mean, I could care less, but it's pretty down there on my personal wishlist. :/
(btw, not a diss at proposing it. it'd be pretty neat. I just have tons of api needs that I'd consider more important)
Not taken as such. What are some of the api improvement that you're particularly interested in, if you don't mind my asking?
In no particular order (and some could be implemented in terms of others): forums access, typed events (instead of plain strings), typed hospital/jail timings, warbase access or batched user calls, users by nick, search (users, factions, etc), oc... Non-exhaustive list from the top of my head. If I were to search through my users' feature requests, I could probably double this. :P
Some of these are certainly not as important or prominent as this thread's topic, but I don't see the lack of API keys flexibility a real blocker so far. There are too few developers working on api stuff-- it's easy enough taking care of that with good ol' trust.
I also would particularly enjoy seeing batched user calls and cleanup of null attributes, which are sometimes 0, sometimes "", and sometimes null.
The nulls thing'd be awesome. d:
I was thinking a bit more about the multiple keys thing and came to the conclusion I don't think it's a net gain. Most people barely know what an api key is, and having the security on their hands doesn't seem that much better (could be wrong). If they were to implement better security, I say go full on authenticated services/oauth, so that if a creator goes rogue they can revoke every api key given to the service.
so kinda similar to my somewhat idea, but you could remember the service and i couldn't. lol
-
A copy of how eve online has it implemented would be nice
[image: puu.sh]
This should have been bumped. Oh well defo good info to keep in mind when using scripts.